Session Logout link

Rob Gorrell rwgorrel at uncg.edu
Tue Aug 19 21:47:05 EDT 2014


I'm not sure I can help you. Based on my understanding, what I've been
trying to convey is the FederationMetadataUrl parameter you speak of only
applies to an ADFS setup and is not relevant (or even accessible) to a SAML
setup, so I am confused as to why you are hung up on it or why you even
have a value there in the first place. In a SAML setup, the O365 metadata
is stored in a static file on your IdP and your IdP's metadata (ie signing
certificate) is uploaded directly to you O365 by using the
-SigningCertificate param of the Set-MsolDomainAuthentication cmdlet...
there is no url involved for metadata retrieval, on either side.

The Get-MsolFederationProperty cmdlet that shows the FederationMetadataUrl
property you speak of only applies to ADFS Federated domains and is far as
I can tell is useless for SAML... in fact if I run it, it will error
telling me my domain isn't federated with ADFS (though its working and
federated with SAML). Remember, Microsoft speak for "federating" is
referring a specific product, ie WSFed/ADFS... using Shibb/SAML is not
federating with O365, but just a special kind of authentication
configuration somewhere between a Managed and Federated domain... so expect
most of the cmdlets with "Federating/Federation" in them to not apply to a
SAML setup.

-Rob



On Tue, Aug 19, 2014 at 3:43 PM, Farzan Qureshi <fqureshi at rosmini.school.nz>
wrote:

> Hi Rob,
>
> Have you ever had this issue that when you try to change
> FederationMetadataUrl it doesn't change even if you change authentication
> to Managed and then change back with federation parameters. I have changed
> it to managed to change the logouturl and now when I am trying to federate
> it with correct parameters in single command it is not changing
> FederationMetadataUrl. It changes everything but not FederationMetadataUrl.
>
> I have manually typed the command and also made sure that $variable holds
> the correct link to SAML metadata.
>
> Would you please help me? It's broken now which I didn't want to.
>
> Thanks.
>
>
> On 20 August 2014 09:01, Farzan Qureshi <fqureshi at rosmini.school.nz>
> wrote:
>
>> Bugga!! :( That's not good :( I don't want to break anything.
>> Any how shall I set LogOffUri to
>> https://idp.rosmini.school.nz/idp/logout.jsp
>> ?
>>
>>
>> On 20 August 2014 08:57, Rob Gorrell <rwgorrel at uncg.edu> wrote:
>>
>>> This is what I was saying in the other thread... it doesn't like
>>> incremental changes here. You need to set your domain back to managed and
>>> then toggle it back to saml federated with all the params correctly set at
>>> once through this cmdlet
>>>
>>> Rob
>>> On Aug 19, 2014 4:53 PM, "Farzan Qureshi" <fqureshi at rosmini.school.nz>
>>> wrote:
>>>
>>>> Hi Rob,
>>>>
>>>> This is what I am doing:
>>>>
>>>> Set-MsolDomainAuthentication -DomainName $dom -Authentication Federated
>>>> -LogOffUri $logouturl
>>>>
>>>> But when I get properties it shows:
>>>>
>>>> PassiveClientSignOutUrl         : https://idp.rosmini.school.nz/logout
>>>>
>>>>
>>>> It is not changing it.
>>>>
>>>>
>>>> On 20 August 2014 08:49, Farzan Qureshi <fqureshi at rosmini.school.nz>
>>>> wrote:
>>>>
>>>>> Shall I set LogOffUri to https://idp.rosmini.school.nz/idp/logout.jsp?
>>>>>
>>>>>
>>>>> On 20 August 2014 08:49, Farzan Qureshi <fqureshi at rosmini.school.nz>
>>>>> wrote:
>>>>>
>>>>>> Ok please wait let me check.
>>>>>>
>>>>>>
>>>>>> On 20 August 2014 08:46, Rob Gorrell <rwgorrel at uncg.edu> wrote:
>>>>>>
>>>>>>> I get a powershell error, because that cmdlet only works for an ADFS
>>>>>>> federated domain, not an SAMLP one.
>>>>>>> For SAML, you need to use the LogOffUri parameter from
>>>>>>> Set-MsolDomainAuthentication cmdlet...
>>>>>>>
>>>>>>> -Rob
>>>>>>>
>>>>>>>
>>>>>>> On Tue, Aug 19, 2014 at 4:42 PM, Farzan Qureshi <
>>>>>>> fqureshi at rosmini.school.nz> wrote:
>>>>>>>
>>>>>>>> Thanks Nate and Rob.
>>>>>>>>
>>>>>>>> Rob, when you run this command on your server to get properties:
>>>>>>>> Get-MsolFederationProperty -DomainName UNCG.EDU
>>>>>>>>
>>>>>>>> What you get against PassiveClientSignOutUrl?
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> On 20 August 2014 02:44, Rob Gorrell <rwgorrel at uncg.edu> wrote:
>>>>>>>>
>>>>>>>>> per Nate's link, you will need to configure and point this URL to
>>>>>>>>> your logout.jsp template.
>>>>>>>>> For me, the URL looks like: https://idp.uncg.edu/idp/logout.jsp
>>>>>>>>>
>>>>>>>>> -Rob
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> On Mon, Aug 18, 2014 at 11:40 PM, Farzan Qureshi <
>>>>>>>>> fqureshi at rosmini.school.nz> wrote:
>>>>>>>>>
>>>>>>>>>> Hi,
>>>>>>>>>>
>>>>>>>>>> I have defined logout URL in Office 365 as
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> PassiveClientSignOutUrl         :
>>>>>>>>>> https://idp.rosmini.school.nz/logout
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> But I get following error when a user logs out, we get:
>>>>>>>>>>
>>>>>>>>>> Not Found
>>>>>>>>>>
>>>>>>>>>> The requested URL /logout was not found on this server.
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> And this is what I have in address bar:
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> https://idp.rosmini.school.nz/logout?SAMLRequest=nZHLasMwEEV/xWgvP2InsURscAkBQx7QNKVkUxRFbkRtydWMofTra7tetJtSupyZO/fOkVYgmppv7Yvt8F69dQrQe29qA3wYZKRzhlsBGrgRjQKOkh%2BL3ZbP/JC3zqKVtibeul/TRqC2JiM3xBZ4EOhr6zsLjTbaB3mztvbNR1CPUcQr1xl5TpcXlqRyQdlyIWgiLgm9sIjRSIm5YnMZL6Uk3qNyMDr3of0iQKdKAygM9q0wSmiY0og9hDGPZzyJz8TLVyPWKHV/5hEAyg0MJB9klboqNzLxnZY9ia3wYGpt1Cr4Zj9l7Xu7cv2PLG9jXSPwd/nQ0VdajVLeDg8CqAySvMTF3W3ztD%2B/Ho6b9HQ8bVXBiiybbvw6K5%2BqH/%2BcfwIOPK35&RelayState=A5gGBk4RnOLcU156TZ*rehh95QXq&SigAlg=http://www.w3.org/2000/09/xmldsig%23rsa-sha1&Signature=lKOQ/zwElEh01I1liHa5woG27K%2B/UrlFYsF/Gt5VHMoyaDhpvEQ5%2BXLjkuA31F4AdD%2B5eELvAMe8%0D%0APNQaMi3Jocn5f00CRjTMX%2BeOVNYr/aXhS5FaTv1OyEJ0AbJkpb/mTXHmmotDcQUc%2ByHCA65YYqut%0D%0A3HT0mP1T6222tmqszbsAZClaZjvuOwBN1eFxdve7d7Iw1frKlrJqIHuVkTN%2BPomHzUyJrZu5nYOy%0D%0Ay%2B/xxM%2B70VBfy2NRWTqL1PEBLr7NH%2B/4bdl%2BIwANf4dG2xXg3msBpqiyegFuJxvxOgEkgFlGuTfV%0D%0AWy5Kxal1AkD5wVJCx4LN9Rfah5GsYC7AyH3AKQ%3D%3D
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> How I can define what happens when a user sign out? What is the
>>>>>>>>>> correct link to sign out?
>>>>>>>>>>
>>>>>>>>>> --
>>>>>>>>>> *Farzan Qureshi* | Network Administrator & Help-desk Support |
>>>>>>>>>> Rosmini College | (09) 487 0 530
>>>>>>>>>>
>>>>>>>>>> This email and any files transmitted with it are confidential and
>>>>>>>>>> intended solely for the use of the individual or entity to whom they are
>>>>>>>>>> addressed. If you have received this email in error please notify the
>>>>>>>>>> system manager (admin at rosmini.school.nz). Please note that any
>>>>>>>>>> views or opinions presented in this email are solely those of the author
>>>>>>>>>> and do not necessarily represent those of the company. Finally, the
>>>>>>>>>> recipient should check this email and any attachments for the presence of
>>>>>>>>>> viruses. Rosmini College accepts no liability for any damage
>>>>>>>>>> caused by any virus transmitted by this email.
>>>>>>>>>>
>>>>>>>>>> --
>>>>>>>>>> To unsubscribe from this list send an email to
>>>>>>>>>> users-unsubscribe at shibboleth.net
>>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> --
>>>>>>>>> Robert W. Gorrell
>>>>>>>>> Systems Architect, Identity and Access Management
>>>>>>>>> University of NC at Greensboro
>>>>>>>>> 336-334-5954
>>>>>>>>> PGP Key ID B36DB0CA
>>>>>>>>>
>>>>>>>>> --
>>>>>>>>> To unsubscribe from this list send an email to
>>>>>>>>> users-unsubscribe at shibboleth.net
>>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> --
>>>>>>>> *Farzan Qureshi* | Network Administrator & Help-desk Support |
>>>>>>>> Rosmini College | (09) 487 0 530
>>>>>>>>
>>>>>>>> This email and any files transmitted with it are confidential and
>>>>>>>> intended solely for the use of the individual or entity to whom they are
>>>>>>>> addressed. If you have received this email in error please notify the
>>>>>>>> system manager (admin at rosmini.school.nz). Please note that any
>>>>>>>> views or opinions presented in this email are solely those of the author
>>>>>>>> and do not necessarily represent those of the company. Finally, the
>>>>>>>> recipient should check this email and any attachments for the presence of
>>>>>>>> viruses. Rosmini College accepts no liability for any damage
>>>>>>>> caused by any virus transmitted by this email.
>>>>>>>>
>>>>>>>> --
>>>>>>>> To unsubscribe from this list send an email to
>>>>>>>> users-unsubscribe at shibboleth.net
>>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> --
>>>>>>> Robert W. Gorrell
>>>>>>> Systems Architect, Identity and Access Management
>>>>>>> University of NC at Greensboro
>>>>>>> 336-334-5954
>>>>>>> PGP Key ID B36DB0CA
>>>>>>>
>>>>>>> --
>>>>>>> To unsubscribe from this list send an email to
>>>>>>> users-unsubscribe at shibboleth.net
>>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> --
>>>>>> *Farzan Qureshi* | Network Administrator & Help-desk Support |
>>>>>> Rosmini College | (09) 487 0 530
>>>>>>
>>>>>
>>>>>
>>>>>
>>>>> --
>>>>> *Farzan Qureshi* | Network Administrator & Help-desk Support |
>>>>> Rosmini College | (09) 487 0 530
>>>>>
>>>>
>>>>
>>>>
>>>> --
>>>> *Farzan Qureshi* | Network Administrator & Help-desk Support | Rosmini
>>>> College | (09) 487 0 530
>>>>
>>>> This email and any files transmitted with it are confidential and
>>>> intended solely for the use of the individual or entity to whom they are
>>>> addressed. If you have received this email in error please notify the
>>>> system manager (admin at rosmini.school.nz). Please note that any views
>>>> or opinions presented in this email are solely those of the author and do
>>>> not necessarily represent those of the company. Finally, the recipient
>>>> should check this email and any attachments for the presence of viruses. Rosmini
>>>> College accepts no liability for any damage caused by any virus
>>>> transmitted by this email.
>>>> --
>>>> To unsubscribe from this list send an email to
>>>> users-unsubscribe at shibboleth.net
>>>>
>>>
>>> --
>>> To unsubscribe from this list send an email to
>>> users-unsubscribe at shibboleth.net
>>>
>>
>>
>>
>> --
>> *Farzan Qureshi* | Network Administrator & Help-desk Support | Rosmini
>> College | (09) 487 0 530
>>
>
>
>
> --
> *Farzan Qureshi* | Network Administrator & Help-desk Support | Rosmini
> College | (09) 487 0 530
>
> This email and any files transmitted with it are confidential and intended
> solely for the use of the individual or entity to whom they are addressed.
> If you have received this email in error please notify the system manager (
> admin at rosmini.school.nz). Please note that any views or opinions
> presented in this email are solely those of the author and do not
> necessarily represent those of the company. Finally, the recipient should
> check this email and any attachments for the presence of viruses. Rosmini
> College accepts no liability for any damage caused by any virus
> transmitted by this email.
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140819/15a9da40/attachment-0001.html 


More information about the users mailing list